شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Careers

Candidate privacy notice

This notice explains how we process your data when you apply for a role with us or join the talent network, and supplements the general privacy policy.

Last updated: 2 October 2026

Scope

This notice applies to everyone who applies for a role through the careers portal on datasec.sa or agrees to join the talent network. The controller is Data Security for Cyber Security (DataSec), commercial registration 1010752666, and the privacy contact is info@datasec.sa.

What we collect

  • Identity and contact data: name, email, mobile number, city and a professional profile link if you add one.
  • Your CV in PDF or DOCX, with the qualifications, experience, skills and certifications it contains.
  • Your answers to role questions, such as years of experience, professional certifications and availability.
  • Your consents: to assess the application, to the talent network (optional) and to WhatsApp contact (optional).
  • Interview notes and hiring-team evaluations during the application stages.
  • Technical data: submission time and a salted hash of the IP address for abuse prevention.

We do not collect sensitive data or personal characteristics unrelated to the role's requirements, and the form does not ask for them. Please do not include such data in your CV; if it appears there, it is not used in the evaluation.

Automated CV reading

When this feature is enabled, the recruitment system uses an AI model through the Anthropic API to read the CV into structured fields (experience, skills, certifications) and to compare the text with the published role criteria.

  • Identity data (name and contact details) is removed from the text before it is sent, and the data is not used to train models.
  • The model's output is advisory only: a summary and suggestions that cite the part of the CV they rely on.
  • The system makes no decision about your application. Acceptance, rejection and moving between stages are decisions made and recorded by a member of the hiring team.
  • You can ask for an explanation of any decision or object to it through info@datasec.sa.

Purposes and legal basis

  • Assessing your application for the specific role and communicating with you about it: with your consent at submission, and as a pre-contractual step towards an employment contract.
  • Keeping your data in the talent network: with a separate, optional consent that you can withdraw at any time.
  • WhatsApp contact: with a separate, optional consent.
  • Protecting the portal from abuse and evidencing compliance: legitimate interest.
  • Verifying qualifications and references before hiring: with prior notice to you and only at the offer stage.

Who sees your data

  • The hiring team and the managers involved in the role inside DataSec, with role-based permissions and an audit log of every access.
  • The company server in a LeaseWeb data centre in the Netherlands (CVs, in private storage), the Neon database in Frankfurt, Germany (application data), and Cloudflare for delivering and protecting the site.
  • Microsoft 365 for notification and confirmation messages.
  • Anthropic when automated CV reading is enabled, with identity-stripped text only.
  • The recruitment system (Zoho Recruit) when in use.
  • WhatsApp (Meta) if you choose to be contacted through it.

We do not share your data with other recruiters or with a current or former employer.

Retention

  • Application: 12 months from the last activity on the application. After that the data is automatically anonymised and the CV, notes and automated reading results are deleted.
  • Talent network: 24 months from the date of your consent, unless you withdraw it earlier.
  • Hired candidates: data moves to the employee file and is governed by HR policies.
  • You can request deletion at any time before these periods end.

Your rights

You have the right to access your data and obtain a copy, correct it, request its deletion, withdraw any consent and object to processing in the cases the Personal Data Protection Law allows. Submit your request through the "Request about my data" form on the privacy policy page or via info@datasec.sa, and we respond within 30 days of receiving a verified request. You also have the right to lodge a complaint with the Saudi Data and AI Authority.

Recruitment fraud warning

We accept applications only through the careers portal on datasec.sa and contact candidates only from email addresses ending in @datasec.sa. We never ask for fees, payments or bank details at any stage of recruitment. If you receive a message claiming to be from DataSec that does not match this, do not respond and report it to info@datasec.sa. Details are on the recruitment verification page.